Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Comment It only works with no scarcity (Score 5, Insightful) 503

The Star Trek economy only works with no scarcity. And while there is a surplus of labor, there is NOT a surplus or resources or energy. And energy is the big one here, as everyone keeps telling us. Sure there is solar, and wind, but they run up against some rather hard resource limitations. (Especially plastics which depend on oil...)

Comment Re:Yeah (Score 2) 47

I was just noticing the other day that a number of emacs lisp packages I use on a regular basis hadn't had any development work in 5-10 years.

If it works, why change it? The SmallWall project was immune to all of the SSL bugs in the last year because we use an old version that does not have these new and buggy features... Of course, this rating system would ding us for that... :)

Comment Re:Excellent idea (Score 2) 47

I agree that it is a very good idea. But the execution leaves a lot to be desired.

An attacker might e.g. get commit rights to several low-activity projects, insert malicious code, and wait for people to download updates and become easily exploitable.

Their rating system actually encourages this. If you have tight controls on commits, like perhaps 1 or two people who review code and actually make the commits, you are "at risk." So go ahead and give that NSA guy commit access...

Comment Re:Stop performing studies (Score 1) 47

What they did is getting a basic overview of which projects need most attention.

No, they have a lit of project that rate in their arbitrary definition of "risk." Have a nice and stable project that is not on the feature of the week train? High risk, because there are not enough updates. How about a hidden development svn, with a public mirror that makes all contributions look like they come from one person? Oh, that is very high risk... By their metrics, "Hello World" is the riskiest program on the planet.

Comment Re:Just block them (Score 2) 130

Delete stuff from the Internet... Hmmm... Sounds like a wonderful idea. How?

Actually it is a terrible idea, even if it could work, because looking at how the code progressed is how you learn. Not to mention that I can patch and old version to fix the vulnerability, but not have to move to the new and incompatible version.

Slashdot Top Deals

What this country needs is a good five dollar plasma weapon.

Working...